Meta’s Muse Doesn’t Declare Itself. Here’s Why That Matters
Meta’s public debut of Muse earlier this month didn’t just launch a new product; it propelled a new class of web traffic at consumer scale.
Agentic browsing is an AI system that doesn’t just answer a question or summarize a page. Instead, it operates a real browser on a person’s behalf, maintaining a logged-in session across multiple steps, clicking through a multi-page flow, filling in forms, and completing an action with a real-world consequence.
That’s a meaningfully different category of web traffic from the crawlers and scraping bots the industry has spent two decades learning to handle: a crawler fetches a page and moves on; an agentic browser sticks around, remembers where it is, and finishes the job.
Muse is Meta’s entry into that category, pitched as “the world’s first personal AI agent built for everyone.” It shops, books, and checks out on a person’s behalf, running inside its own sandboxed browser environment Meta calls a Sentinel VM.
Shopify moved fast to welcome that traffic. Amazon moved just as fast to block it. Somewhere in between sit the rest of the web’s merchants, who now have to answer a question that wasn’t on their roadmap a month ago: what do you do when a real customer’s intent arrives wrapped in automation you never asked for?
Muse doesn’t tell you it’s Muse
There’s no custom User-Agent, no declared header that says “an AI agent is driving this session.” Every request we’ve captured presents as an entirely unremarkable desktop Chrome browser on Linux.

The sessions we’ve observed egress through generic edge infrastructure, Cloudflare or Fastly-owned address space, not any IP range Meta documents or attributes to Muse. And unlike the crawlers the web has spent two decades learning to accommodate, there’s nothing to check that identity against: no published IP allowlist the way Googlebot or Bingbot maintain, no cryptographically signed requests under the emerging Web Bot Auth standard.
The browser tells a different story
With very little at the network level to check, the only signals left are client-side: whatever the browser itself reports back once our JavaScript actually runs on the page. None of that is declared anywhere, and it has to be inferred.
The requests look clean, but the browser underneath doesn’t. When we compared live Muse sessions captured on completely unrelated sites, the overlap in environmental signal was almost total, the kind of match you only get from the same sandboxed image being deployed instead of two users who happen to run similar setups. Hardware characteristics, rendering behavior, and browser internals that a genuinely diverse population of desktop users would never reproduce identically kept showing up, identically, every time.
That’s a meaningfully different foundation than a signed, verifiable identity, though.
It’s not who. It’s why
As agentic commerce gets normalized and merchants start writing explicit policies for “known, legitimate agents,” impersonating a trusted one becomes more valuable than impersonating a human.
In fact, 7 in 10 sites we tested for our 2026 State of Bot & Agent Security Report allowed a spoofed AI agent or crawler through without a challenge, simply because the request claimed to be GPTBot, ClaudeBot, or a similar trusted identity.
A fingerprint that earns a free pass is a fingerprint worth copying, and we should expect the same actors we’ve tracked for years—scalpers, scraper networks, fraud rings—to start dressing their traffic up as Muse, or whatever agent a platform has chosen to trust.
But even a perfectly genuine, unspoofed Muse session doesn’t answer the question that actually matters: what is this traffic trying to do?
Two requests with an identical fingerprint can carry completely different intent. One is a single agent completing a checkout on behalf of the person who opened it. The other is a fleet of agents, real or impersonated, working a limited ticket drop or scraping a full catalog faster than any shopper could browse it. Fingerprinting tells us what kind of client is making the request. It’s never been enough, on its own, to tell us whether the request should be allowed.
That’s the principle underneath everything we build at DataDome. A signature, real or forged, narrows down identity. The decision that actually protects a business has always come from intent: what this traffic is trying to accomplish, and whether that matches how a legitimate visitor, human or agent, behaves. Muse is just the newest reason that distinction is worth restating.
Muse won’t be the only agent showing up this way for long. OpenAI, Google, Perplexity, and a fast-growing list of other players are all building their own version of the same idea: an AI that browses and transacts on a person’s behalf instead of just answering them. Each will bring its own environment, its own quirks, its own version of an unremarkable-looking browser that doesn’t say what it is. The identity question will keep resetting with every new agent this space produces.
DataDome customers can now see traffic from Muse’s cloud browser in their Agentic Trust dashboard, nested under the Agentic Browser category, with full control over how to respond to it.
Want to know what’s browsing your site? Book a demo to learn more about DataDome.